《MIDAS行动——追踪欺诈性金融项目组织.pdf》由会员分享,可在线阅读,更多相关《MIDAS行动——追踪欺诈性金融项目组织.pdf(44页珍藏版)》请在三个皮匠报告上搜索。
1、#BHEU BlackHatEventsInformation Classification:GeneralOperation MIDASTracking Fraudulent Financial Program OrganizationsSung-Wook JangYong-Hyun Kim(copy_and_paster)Financial Security Institute#BHEU BlackHatEvents#BHEU BlackHatEventsInformation Classification:General Sung-Wook,Jang:Senior,Financial S
2、ecurity Institute(FSI)6 years of CTI,DFIR,Malware analysis Yong-Hyun,Kim:Principal,Financial Security Institute(FSI)8 years of SOC&CTI&DFIR,4 years of DAST SW Developer Past presentationsFS-ISAC 2023 APAC:Building CTI Service from 2B NIDS events over 8 yearsISCR 2019(KNPA)-Fight Against Cybercrime:G
3、ANDCRAB Threat GroupsAbout us#BHEU BlackHatEventsInformation Classification:GeneralBackground Fake Trading System Scam A Cybercrime that impersonates an investment professional to trick and defraud people into using a fake trading system*HTS(Home Trading System),MTS(Mobile Trading System)In Korea,th
4、ere are many cases that impersonates existing financial companies Terms in this presentation Supplier:An organization that develops and distributes fake HTS Affiliate:An organization that uses fake HTS to commit fraud(there are several groups)3rd party service:Legitimate&Not Legitimate Services(e.g,
5、Youtube,Money Launderers,Messenger Service,)SupplierAffiliate?#1Affiliate?#nVictims#BHEU BlackHatEventsInformation Classification:General Monitoring social media threat information A tweet found about fake HTS threat information on Twitter(r3dbU7z,22.10)a lot of screenshot files were being exposed f
6、rom a specific port not only were victims being exposed,but also screenshots of the criminals!Initial Findings(1/2)*https:/ BlackHatEventsInformation Classification:GeneralInitial Findings(2/2)Victims?or Criminals?Title bar on Trading SWGeneral Manager keywordMultiple Execution of HTS Scam messages